Few HIPAA documents are as widely signed and as rarely read as the business associate agreement, or BAA. Yet it is the contract that governs how an outside company may use and protect resident information on your behalf. When a vendor has a breach, the BAA often determines who must notify whom, how quickly and who bears responsibility.
This article explains in plain terms who needs a BAA, what it should include and what administrators should verify.
Under HIPAA, a business associate is a person or company that creates, receives, maintains or transmits protected health information on behalf of a covered entity, or provides certain services to it involving that information. Examples in a long-term care setting commonly include:
EHR and clinical software vendors
Managed IT service providers with access to systems holding PHI
Cloud hosting and backup providers
Billing and revenue cycle companies
Consulting, legal and accounting firms that see PHI
Shredding and records storage companies
eFax and email service providers handling PHI
Telehealth platforms
Some relationships are a gray area. HHS has said that a cloud provider that stores encrypted PHI is a business associate even if it does not hold the encryption key. A different example is a janitorial service with incidental exposure, which generally is not a business associate but still needs confidentiality terms. When uncertain, ask your privacy officer or counsel.
The HIPAA Privacy and Security Rules specify required elements. A compliant BAA generally:
Describes the permitted and required uses and disclosures of PHI
Prohibits any use or disclosure not allowed by the contract or by law
Requires the business associate to use appropriate safeguards and comply with the Security Rule for electronic PHI
Requires the business associate to report to you any use or disclosure not permitted, including security incidents and breaches of unsecured PHI
Requires subcontractors that handle PHI to agree to the same restrictions
Makes PHI available so you can respond to resident requests for access, amendment and an accounting of disclosures
Requires return or destruction of PHI at contract end, when feasible
Allows you to terminate the contract if the business associate violates a material term
Many BAAs are written by the vendor. Before signing, pay attention to:
The HIPAA Breach Notification Rule requires business associates to notify the covered entity without unreasonable delay and no later than 60 days after discovery. Your own deadlines may start earlier depending on the circumstances, so negotiate a much shorter window in your agreement, such as a few business days for an initial notice.
Ask which subcontractors will touch your data and where they are located.
Some vendors try to cap liability very low. Consider whether the cap is reasonable for the risk and whether cyber insurance covers gaps.
Confirm that data stays in the United States if that matters to you, and that you can get your data back in a usable format.
See whether you can request security documentation or reports.
No BAA at all for a vendor that clearly handles PHI
BAAs signed years ago and never updated after services changed
Missing BAAs for subcontractors or minor tools such as a scanning app
Nobody knows where the signed copies are stored
Expired relationships where the vendor still has access to data
Staff signing up for free online tools with resident information and no agreement
Maintain a vendor list with columns for vendor name, services, whether PHI is involved, BAA signed date, renewal or review date and an internal owner. Review it annually and whenever a new tool is introduced. Pair it with a rule that staff must consult the privacy or IT lead before adopting any new software that might touch resident data.
Retain BAAs for at least six years, in line with HIPAA's documentation requirements.
If you provide services to other covered entities, you may be a business associate yourself. In that case you are directly responsible for Security Rule compliance and must sign BAAs with your own subcontractors.
HHS publishes sample BAA provisions on its website, which are a useful starting reference. Your attorney should review final agreements. UnityCare IT signs BAAs with healthcare clients and can help you inventory vendors, spot missing agreements and understand the technical safeguards described in them.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172